Highly Customized Phishing Attack
高度客製化釣魚攻擊
Operation & Monitoring
Risk Description
When an employee receives an email imitating a supervisor's writing style and referencing an actual recent project; due to unmitigated control gaps, the content is natural and the context plausible, triggering external stakeholder impacts and causing the employee follows the instructions before realizing it is fraudulent, and existing phishing awareness training proves entirely ineffective.
Framework Mappings
NIST AI 600-1Information Security
MITRE ATLASAML.T0052
EU AI ActArt.50
NIST AI RMFMANAGE 2.4
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 4
Risk Treatment & Implementation Guidance
Deploy advanced email security detecting highly tailored phishing that mimics writing style and plausible context; Require out-of-band verification for financial and sensitive instructions beyond email content; Train staff on social-engineering awareness covering AI-enhanced personalized attacks